Fix fabric-native-components.md #246
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
The documentation mentioned
yarn upgrade rtn-centered-textwould sync the latest changes from the localRTNCenteredTextpackage into thenode_modulesfolder. In fact that's wrong and even worse, it opens a door to malicious package injection. 2 days ago someone posted a package on npmjs with the namertn-centered-textthat uploads information like private/public IP, local operating system, etc. to some discord channel.https://www.npmjs.com/package/rtn-centered-text
This is an excerpt of the collected user information:
This data is then uploaded to:
https://discord.com/api/webhooks/1306068586086793297/5ERJ-0yumqHWIUMiaww5_SdUkVAptuIxMIUMbTaEY--c5IyIDDA4aYHdKIi6YwYJ_7mS
I've reported the issue already to npmjs, but please close the door here as well. A simple
yarn addsyncs a local package.